Privacy Policy
This Privacy Policy explains how the Let's Track mobile app for Android and iOS ("Let's Track", "the app", "we", "us") collects, uses, stores, shares, and protects information. Let's Track finds parcel tracking numbers in your shipping emails and shows the delivery status of your packages. By using the app you agree to this policy.
Summary
- The app works without an account. We don't ask for your name, phone number, or email address to use it.
- Your emails are read and analyzed only on your device. Email content never reaches our servers.
- Tracking numbers found in your emails are only suggested to you. A number leaves your device only after you choose to add it, so we can check its delivery status.
- We don't sell data, don't show ads, and don't use your data to train AI models.
1. Information we access and collect
1.1 Google user data (Gmail)
Connecting a Gmail account is optional. If you choose to connect one, you sign in with
Google and grant Let's Track read-only access to your email through the Gmail API scope
https://www.googleapis.com/auth/gmail.readonly. With this access the app:
- reads email messages (subject, sender, and body text) directly from Google to your device;
- analyzes them on your device with a built-in model to find parcel tracking numbers;
- keeps on your device the tracking numbers it finds and a short piece of the surrounding email text, and shows them to you as suggestions, so you can see where each number came from and decide whether to add it;
- keeps on your device, in the operating system's secure storage, the information needed to access the mailbox (your Google account email address and authorization data).
The app never sends, modifies, labels, or deletes your emails.
Email content, email addresses, and Google authorization data are never sent to our servers or to any third party. The only information derived from your emails that may leave your device is a tracking number (and, optionally, its carrier) that you have explicitly chosen to add to your packages (see 1.4). Numbers you don't add never leave your device.
1.2 Other mailboxes (IMAP)
You can also connect a mailbox of another provider using its IMAP settings. The same rules apply: the app connects to your mail server directly from your device, analyzes emails on your device, and stores the mailbox credentials only in the device's secure storage.
1.3 Information you enter
Tracking numbers you add by hand or scan with the camera, and the names you give to packages, are stored on your device. The camera is used only while you scan a barcode; images are not saved or sent anywhere.
1.4 Information sent to our server
To check delivery status and send you notifications, the app sends to our server:
- the tracking numbers of the packages you added (by hand, by scanning, or by confirming a number suggested from your email) and, optionally, the carrier (delivery service) of each one;
- a random device identifier generated by our server (not linked to your identity);
- your device platform (Android or iOS);
- a push notification token from Firebase Cloud Messaging, only while notifications are allowed on your device.
Our server also receives your IP address as part of normal network communication; it is used only to deliver responses and to protect the service from abuse.
2. How we use information
- to find tracking numbers in your emails and show them in the app;
- to check the delivery status of your packages with postal and courier services;
- to send you push notifications when the status of a package changes;
- to keep the service secure and working (rate limiting, error diagnostics, aggregate usage metrics that contain no personal data).
We don't use your information for advertising, profiling, or marketing.
3. Google API Services: Limited Use
Let's Track's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- we use Gmail data only to provide the user-facing feature of finding parcel tracking numbers in your emails;
- we don't transfer Gmail data to others, except tracking numbers you explicitly chose to add, which are sent to tracking services to provide this feature, as described in this policy, or when required by law;
- we don't use or transfer Gmail data for serving advertisements, including personalized or interest-based ads;
- we don't sell Gmail data and don't use it to determine credit-worthiness or for lending purposes;
- no person reads your Gmail data: emails are processed automatically on your device only;
- we don't use Gmail data to develop, improve, or train generalized or non-personalized AI or machine learning models.
4. Sharing and disclosure
We share information only with the service providers needed to run the app:
- Package tracking services (for example, 17TRACK and postal or courier services) receive tracking numbers to return delivery status.
- Firebase Cloud Messaging (Google) receives the push token and the notification text to deliver notifications to your device.
- Fly.io hosts our server and the data described in 1.4.
We may disclose information if required by law or to protect the rights and safety of users. We don't sell or rent information to anyone.
5. Storage, retention, and deletion
- Data on your device (packages, tracking history, email snippets, mailbox credentials) stays there until you delete it in the app, disconnect the mailbox, or uninstall the app.
- When you disconnect a mailbox in the app, its credentials are removed from the device.
- On our server, the tracking numbers of a package are removed when you delete the package in the app. A device that has not contacted the server for 30 days is deleted together with its tracking numbers and push token.
- You can revoke Let's Track's access to your Google account at any time at myaccount.google.com/permissions.
- To ask us to delete data stored on our server, email us at the address below; we will do so within 30 days.
6. Security
All network communication uses HTTPS (TLS). Mailbox credentials are stored in the operating system's secure storage (Android Keystore / iOS Keychain). Access to the server is limited to the developer.
7. Children
Let's Track is not directed to children under 13, and we don't knowingly collect information from them.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or object to the processing of your information. Most data lives only on your device and is under your control. For anything stored on our server, contact us.
9. Changes to this policy
We may update this policy. The current version is always on this page with its effective date. If changes affect how we use Google user data, we will notify you in the app before they take effect.
10. Contact
Questions about this policy or your data: oleksandr.kurinnyi.work@gmail.com